Departmental COOP Template

advertisement
CONTINUITY OF OPERATIONS PLAN ANNEX
Student Financial Aid and Scholarships
April 2013
The completed Department COOP Annex should be sent electronically to the
Business Continuity Office. Contact Lynn Daley at 585-475-7812 or
lbdrmss@rit.edu for assistance
Table of Contents
1. Background ............................................................................................................................ 2
2. COOP Information.................................................................................................................. 3
2.1 Introduction ...................................................................................................................... 3
2.2 Mission Essential Functions ............................................................................................. 3
2.3 Personnel and Infrastructure ............................................................................................ 4
2.3.1 Personnel .................................................................................................................. 4
2.3.2 Infrastructure ............................................................................................................. 5
2.4 Chain of Succession and Authority ................................................................................... 5
2.5 Critical Resources ............................................................................................................ 5
2.5.1 Vital Records and Files .............................................................................................. 5
2.5.2 Critical Information Technology Systems ................................................................... 5
2.5.3 Critical Equipment ..................................................................................................... 6
2.5.4 Internal and External Contacts .................................................................................. 6
2.6 Alternate Sites – Work Locations...................................................................................... 7
3 COOP Response .................................................................................................................... 8
3.1 [Department] Response Team ......................................................................................... 8
3.2 Activation and Notification ................................................................................................ 8
3.3 Hazard-Specific Response ............................................................................................... 8
3.3.1 Loss of Resource 1.................................................................................................... 8
3.3.2 Loss of Resource 2.................................................................................................... 8
3.3.3 Loss of IT Service ...................................................................................................... 8
3.3.4 Staffing Shortage ....................................................................................................... 8
3.3.5 Loss of Access to Facility .......................................................................................... 8
4. COOP Exposures................................................................................................................... 9
Continuity of Operations Plan Annex Template
1
Annex - Department
RIT Internal Use Only
1. Background
This departmental Continuity of Operations (COOP) Annex details the specific information
related to the mission essential functions performed by the department in support of RIT’s
mission. It documents key personnel and resources necessary to perform those functions, as
well as establish a chain of succession and authority.
The COOP Annex may be activated as a result of a localized disruption to required resources or
a more wide-spread incident. In the latter case, the Critical Incident Management Team (CIMT)
will have been formed and continuity of operations will be managed by the CIMT in addition to
other consequence management activities the CIMT performs. The leaders of the department
will be integrated into the CIMT (along with other departments who may have been impacted) to
ensure coordination of activities.
A COOP Plan details how a department/agency’s essential functions will be handled in the
event of an emergency or situation that disrupts normal operations, leaving department/agency
facilities damaged or inaccessible. With this goal in mind, the COOP planning process is
designed to answer the following questions:

What essential functions must be performed, regardless of the outside threats?

What personnel are needed to perform those functions?

What resources are needed to perform the essential functions?

How can we ensure that the designated people and resources are prepared to perform
those functions when called upon?
Objectives of the COOP plan are to:

Ensure continuous performance of essential functions at an acceptable level.

Reduce or mitigate disruptions to operations through protection of critical equipment,
records and other assets.

Achieve a timely and orderly recovery and resumption from an interruption or
disruption.
Continuity of Operations Plan – Department Annex
2
Annex - Department
RIT Internal Use Only
2. COOP Information
2.1 Introduction
This section describes the department:

Vision and Mission

Goals and Objectives

General information regarding processes and other key information
2.2 Mission Essential Functions
Mission essential functions are those department-specific duties or responsibilities that, if left
unperformed, would substantially impact the ability of RIT to fulfill its mission.
Table 1. Recovery Priorities
Tier
1
2
3
4
Recovery Time
Objective
Recovery Priority
IMMEDIATE
These functions involve those with the direct and immediate effect on
the agency to preserve life, safety and protect property.
CRITICAL
These functions can be delayed until Tier 1 functions are restored but
must be operational within 72 hours.
NECESSARY
These functions can be delayed until Tier 1 and 2 functions are
established but must be operational within one week.
IMPORTANT
These functions can be delayed until Tiers 1, 2 and 3 are operational.
0 - 24 hours
24 - 72 hours
72 hours to 1 week
1 week to 30 days
Note that priorities may change depending on the time of year, based on critical processing
activities.
Table 2. Functions
Function Name
Description / Steps
Critical Time
Period(s)
Tier

Continuity of Operations Plan – Department Annex
3
Annex - Department
RIT Internal Use Only
2.3 Personnel and Infrastructure
2.3.1 Personnel
This section lists personnel in the Department and the primary function they support (as
described in Table 2). Also shown is the secondary function they can support if primary
personnel are not available.
Table 3. Personnel and Functions
Name
Title
Continuity of Operations Plan – Department Annex
Function
Primary
Function
Secondary
4
Annex - Department
RIT Internal Use Only
2.3.2 Infrastructure
Detail the location(s) (building, floor, etc.) where functions are performed.
2.4 Chain of Succession and Authority
This section identifies personnel who have the authority to make certain decisions, approvals
and disapprovals as well as those to whom the authority is delegated and under what
circumstances.
Table 4. Succession and Authority
Name
Authorities
Primary Delegate
Secondary
Delegate
2.5 Critical Resources
Critical resources are the files, systems and equipment necessary to maintain the continuity of
mission essential functions.
2.5.1 Vital Records and Files
Vital records are those records that if damaged or destroyed would disrupt operations and
information flow, and require replacement or re-creation at considerable expense or
inconvenience.
Table 5. Vital Records
Record, File Name
Type
Electronic, Paper
Location
Purpose
2.5.2 Critical Information Technology Systems
Table 6 . Technology
Name
Continuity of Operations Plan – Department Annex
Description
RTO
RPO
5
Annex - Department
RIT Internal Use Only
Name
Description
RTO
RPO
RTO = recovery time objective – how long the service can be down without significant impact to
functions
RPO = recovery point objective – how much data can be lost (4 hours, 8 hours, 72 hours, etc.)
2.5.3 Critical Equipment
Like critical systems, critical equipment includes specific equipment required to perform mission
essential functions. Each department within the agency provides different services; therefore,
each department has different critical equipment needs. This section should include a complete
list of critical resources for the department, including the quantity, equipment details, vendor or
point of contact, and the contact information for the identified vendor or contact.
Table 6. Critical Equipment
Name
Description
Specifications
2.5.4 Internal and External Contacts
Contacts, vendors and stakeholders the department will need to contact or can assist the
department during a COOP event.
Table7. Contacts
Contact
Organization
Contact Name
Continuity of Operations Plan – Department Annex
Service(s) Provided
Contact
Information
6
Annex - Department
RIT Internal Use Only
2.6 Alternate Sites – Work Locations
This section describes other locations functions can be performed if the primary location is not
available for some reason. Alternate sites can include working from home or another location
on campus.
Continuity of Operations Plan – Department Annex
7
Annex - Department
RIT Internal Use Only
3 COOP Response
This section describes how the department will organize and response to a loss of a critical
resource (people, technology, architecture).
3.1 [Department] Response Team
3.2 Activation and Notification
3.3 Hazard-Specific Response
3.3.1 Loss of Resource 1
3.3.2 Loss of Resource 2
3.3.3 Loss of IT Service
3.3.4 Staffing Shortage
3.3.5 Loss of Access to Facility
Continuity of Operations Plan – Department Annex
8
Annex - Department
RIT Internal Use Only
4. COOP Exposures
Exposures are practices or procedures (or lack thereof) that leave the department susceptible to
interruptions or disruptions to their critical functions. Exposures may include inadequate backup
staff to perform critical functions or vital records are not backed up (or backed up at insufficient
intervals).
Table7. Exposures
Name
Sample:
Travel Expense
Records
Description
Travel expense payment requests submitted
by employees are kept in filing cabinets.
These cabinets are not fire/waterproof, nor
are the paper records scanned and digitized.
Continuity of Operations Plan – Department Annex
Fix
Scan requests to a folder on the
department’s fileshare. The fileshares
are backed up by ITS on a daily basis.
9
Download